Post-Quantum Cryptography

Cyber Insurance and PQC Readiness: What Underwriters Are Starting to Ask

Before 2021, most cyber insurance questionnaires asked whether you had a firewall and an incident response plan. Then ransomware losses climbed steeply enough to move underwriters. The same mechanism exists for post-quantum cryptography. Loss events have not occurred yet, but the architecture of how quantum risk enters the insurance market is visible now.

Cyber Insurance and PQC Readiness: What Underwriters Are Starting to Ask

Cyber Insurance and PQC Readiness: What Underwriters Are Starting to Ask

8 July 2026

Steven Vaile, Director, Quantum Security Defence

<p>Before 2021, most cyber insurance questionnaires asked whether you had a firewall and an incident response plan. Then ransomware losses climbed steeply enough to move underwriters. Within eighteen months of the major 2021 ransomware events, multi-factor authentication went from industry best practice to a warranty condition: absent MFA, your ransomware claim might not pay. That transition happened fast and without a formal announcement. The same mechanism exists for post-quantum cryptography. Loss events have not occurred yet, but the architecture of how quantum risk enters the insurance market is visible now, and preparation is measured in documented artefacts, not in completed migrations.</p>

<h2>The market that will absorb this risk</h2>

<p>The global cyber insurance market was estimated at approximately USD 16 billion in gross written premium in 2023, with forecasts from S&amp;P Global, Munich Re, and Lloyd's of London ranging from USD 29 billion to USD 43 billion by 2027 to 2028 depending on methodology. Lloyd's of London accounts for a significant share of large-account and complex-risk cyber placements. AIG (CyberEdge [ASSUMED: product name current as of knowledge cutoff August 2025; verify with AIG product documentation before publication]), Chubb (Cyber Enterprise Risk Management [ASSUMED: product name current as of knowledge cutoff August 2025; verify with Chubb product documentation before publication]), Beazley, and Munich Re are among the largest global participants.</p>

<p>The pattern that shaped the 2021 to 2023 market hardening is instructive. When ransomware losses became large enough and frequent enough to appear in loss data, underwriting criteria adapted within twelve to twenty-four months. [INFERRED from cyber insurance market reports: Lloyd's, Munich Re, Swiss Re. The 12-24 month adaptation window is an inference from observed market behaviour, not a stated figure from a single Tier 1 source.] That is the structural mechanism. It does not require a policy decision from a regulatory body or an announcement from the market association. Loss data drives criteria, and criteria embed into questionnaires and warranty conditions at renewal.</p>

<p>Quantum risk has not yet generated loss events. A cryptographically relevant quantum computer (CRQC), a machine with sufficient qubit count, error correction, and operational fidelity to break RSA-2048 in a practical timeframe, does not exist as of mid-2026. That is why quantum risk is not currently driving hard underwriting criteria in the way ransomware did. Some underwriters and specialist brokers have begun including quantum-risk language in policy discussions, particularly for large-account renewals and for sectors where data longevity creates harvest-now-decrypt-later exposure. [ASSUMED: the claim that specific underwriters have begun including quantum-risk language requires verification. No Tier 1 or Tier 2 source documents this with specificity as of mid-2026. Treat as informed inference and verify with current broker interviews or published underwriter guidance before stating as confirmed market practice.]</p>

<h2>Lloyd's and the systemic risk machinery</h2>

<p>Lloyd's of London published a systemic risk exclusion for cloud service provider failure (LMA21-042 / NMA5407) in 2023. The mechanism: identify a systemic risk category, name it explicitly in policy wording, and require syndicates to address it. Lloyd's has used this mechanism for cyber war exclusions and state-sponsored attack exclusions. [VERIFIED: Lloyd's LMA21-042/NMA5407 Cyber War and Cyber Operation Exclusion clauses, Lloyd's Market Association, 2023, https://www.lma.org.uk/.] The same structural capacity exists for a quantum decryption exclusion. No Lloyd's document on quantum risk exclusions has been published as of the knowledge cutoff for this article. That absence is a market position, not a confirmation of safety.</p>

<p>Lloyd's "Realistic Disaster Scenarios" (RDS) framework requires syndicates to model their exposure to defined catastrophic events. Quantum decryption of financial infrastructure is not yet a formal RDS scenario. [INFERRED from published Lloyd's market guidance on RDS scope; the specific claim about quantum not yet being a formal RDS scenario requires verification against current Lloyd's publications before citing as fact.] Inclusion as an official RDS scenario would be a market-significant event: syndicates would need to run quantum exposure models for their portfolios, which creates immediate underwriting pressure regardless of whether any policy language has changed.</p>

<p>Munich Re has published research identifying quantum computing as a long-horizon systemic risk to cyber insurance portfolios, citing the potential for widespread decryption of historically captured encrypted data as a correlated loss scenario. [INFERRED from Munich Re's published cyber risk research programme; the specific content of that research requires identification of a concrete published Munich Re report before this claim is included verbatim in the final article.] A correlated loss scenario, where multiple insureds suffer losses from the same systemic event simultaneously, is the category of risk that makes underwriters most cautious. The HNDL scenario, where a CRQC enables mass decryption across sectors, sits directly in that category.</p>

<h2>Three exclusion architectures that could enter the market</h2>

<p>No standard market language for quantum-risk exclusions exists as of mid-2026. [INFERRED from structural analysis of exclusion mechanisms; no Tier 1 or Tier 2 source has published standard market language for quantum exclusions as of the knowledge cutoff.] Three architectures are technically distinguishable and worth understanding before they appear in your renewal documents.</p>

<p>A decryption exclusion would exclude losses arising from decryption of previously captured encrypted data using a CRQC. It is structurally analogous to a war exclusion: a named scenario where the insured's data is compromised by a state or non-state actor using a specific capability. A retroactive exposure exclusion would address loss arising from discovery that captured data held by a third party has been or may be decrypted, triggered by an HNDL event rather than a current-period attack. A quantum-vulnerable encryption warranty would condition coverage on the insured having a documented PQC migration plan, directly parallel to the MFA warranty that became standard after 2021. Breach of the warranty could void coverage for claims arising from cryptographic vulnerabilities.</p>

<p>The MFA precedent is the clearest signal for how the warranty route works. Before large ransomware losses, MFA was best practice but rarely a warranty condition. Underwriters moved because loss data showed that absence of MFA contributed directly to high-severity claims. The same dynamic, loss data demonstrating that absence of PQC planning contributes to claim severity, is the trigger condition for a PQC warranty. That trigger has not fired yet. It will.</p>

<h2>What demonstrating readiness looks like in 2026</h2>

<p>In the near term, the most likely underwriting development is not exclusion language but questionnaire evolution. Cyber insurance application questionnaires already capture MFA deployment, EDR coverage, backup practices, and vulnerability management programme status. These are the preconditions underwriters tested before 2021's hardening, not after it. The questions that are coming, and that you should be able to answer before your next renewal, are approximately these: Does the organisation have a cryptographic asset inventory? Has the organisation assessed its exposure to harvest-now-decrypt-later attacks? Does the organisation have a documented PQC migration plan with progress milestones? [ASSUMED: no published underwriter questionnaire contains quantum-readiness questions as of knowledge cutoff August 2025. Present these as questions that will arrive, not questions currently being asked.]</p>

<p>Demonstrating PQC readiness in the underwriting context requires three documented artefacts. First: a Cryptographic Bill of Materials (CBOM), a structured inventory showing that all asymmetric key uses across your estate have been identified. NIST NCCoE SP 1800-38B provides the methodology. Second: a risk assessment entry documenting the HNDL threat and your data classification by confidentiality lifetime, using the Mosca inequality as the analytical basis. Third: a migration plan with documented milestones, even if migration is not complete.</p>

<p>The Mosca inequality: if x (data protection requirement lifetime) plus y (migration timeline) exceeds z (time before a CRQC), the risk is present now rather than future. For an organisation holding data with a ten-year confidentiality requirement and a three-year migration timeline, the Mosca test is satisfied by any Q-Day estimate before 2039. Expert consensus currently places Q-Day in the 2033 to 2035 range for the first CRQC capable of breaking RSA-2048. [VERIFIED: Mosca, IEEE Security and Privacy, 2018, https://doi.org/10.1109/MSP.2018.3761723. INFERRED for the Q-Day range: consistent with BSI, NCSC, and NSA published frameworks; no single source pins a specific year.] For organisations in most regulated sectors, the Mosca test is already met on their highest-sensitivity data.</p>

<p>These three artefacts also satisfy NIS2 Article 21(1) risk management documentation requirements and ISO/IEC 27001:2022 Annex A 8.24 policy obligations. They are not insurance-specific documents. They serve multiple compliance frameworks simultaneously, which is the efficiency argument for doing the work before the questionnaire arrives.</p>

<h2>Sectors with the highest quantum insurance exposure</h2>

<p>Quantum insurance risk is not uniformly distributed. The sectors where HNDL exposure is highest share two characteristics: data with long mandatory retention periods, and high-value targeting by sophisticated state-level adversaries.</p>

<p>Financial services: trade data, M&amp;A information, and client portfolio data held under MiFID II retention requirements of five to seven years. [VERIFIED: MiFID II Delegated Regulation (EU) 2017/565, Articles 72 to 76.] Healthcare: patient records under HIPAA minimum six-year documentation retention and state-law requirements of seven to ten years from date of service. [VERIFIED: HIPAA 45 CFR 164.530(j).] NHS England records under the NHS Records Management Code of Practice 2021 extend to eight years for adult inpatient records and twenty-five years for maternity records. [VERIFIED: NHS Records Management Code of Practice 2021.] Legal and professional services: privileged client communications and M&amp;A deal materials with an indefinite confidentiality requirement. Defence industrial base: technical specifications and contract information with no fixed end date.</p>

<p>For each of these sectors, the insurance exposure is not hypothetical. A CRQC-enabled decryption event affecting historically captured data in any of these categories is a large, correlated loss. The organisation that has a documented CBOM, a risk register entry, and a migration plan is in a materially different position in that scenario than the one that does not, both in terms of regulatory standing and in terms of what the policy language allows the insurer to argue.</p>

<h2>What to do before your next renewal</h2>

<p>Three concrete actions, in order of urgency. First: complete a CBOM for the ten systems with the highest-sensitivity data. Identify every asymmetric key use, algorithm, and the retention period of the data it protects. This is the foundational document for everything else. Second: create a risk register entry applying the Mosca inequality to your highest-sensitivity data category. Name the threat, calculate the numbers, document the treatment decision. Third: document a migration plan with at least one committed milestone. Deploying hybrid TLS on internet-facing systems (X25519+ML-KEM-768 per NIST FIPS 203) is the concrete first deliverable. It is backwards-compatible and provides HNDL protection for new traffic from the point of deployment.</p>

<p>When the questionnaire arrives at renewal and asks whether you have a cryptographic asset inventory, you want to answer yes. The organisation that cannot answer yes is, at that point, not demonstrating that it has assessed a risk category the underwriting market has already identified. For the governance escalation path to your board on the insurance exposure dimension, see our analysis at <a href="/insights/quantum-risk-board-agenda-cisos/">quantum risk on the board agenda: what CISOs need to present</a>. For the internal business case that includes insurance premium impact as a line item, see <a href="/insights/ciso-quantum-security-investment-case-2026/">the CISO's quantum security investment case for 2026</a>.</p>

Steven Vaile — Director, Quantum Security Defence

View on LinkedIn | View Team | QSecDef Events

Steven Vaile

Steven Vaile

Director, Quantum Security Defence